rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 1 | #!/bin/bash |
| 2 | |
Darin Petkov | 47974d4 | 2011-03-03 15:55:04 -0800 | [diff] [blame] | 3 | # Copyright (c) 2011 The Chromium OS Authors. All rights reserved. |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 4 | # Use of this source code is governed by a BSD-style license that can be |
| 5 | # found in the LICENSE file. |
| 6 | |
| 7 | # Script to enter the chroot environment |
| 8 | |
J. Richard Barnette | 8e6750d | 2011-08-22 12:35:52 -0700 | [diff] [blame] | 9 | SCRIPT_ROOT=$(readlink -f $(dirname "$0")/..) |
| 10 | . "${SCRIPT_ROOT}/common.sh" || exit 1 |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 11 | |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 12 | # Script must be run outside the chroot and as root. |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 13 | assert_outside_chroot |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 14 | assert_root_user |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 15 | |
| 16 | # Define command line flags |
| 17 | # See http://code.google.com/p/shflags/wiki/Documentation10x |
| 18 | DEFINE_string chroot "$DEFAULT_CHROOT_DIR" \ |
| 19 | "The destination dir for the chroot environment." "d" |
| 20 | DEFINE_string trunk "$GCLIENT_ROOT" \ |
| 21 | "The source trunk to bind mount within the chroot." "s" |
David McMahon | 03aeb20 | 2009-12-08 12:47:08 -0800 | [diff] [blame] | 22 | DEFINE_string build_number "" \ |
| 23 | "The build-bot build number (when called by buildbot only)." "b" |
Andrew de los Reyes | 6d0ca16 | 2010-02-12 14:36:08 -0800 | [diff] [blame] | 24 | DEFINE_string chrome_root "" \ |
| 25 | "The root of your chrome browser source. Should contain a 'src' subdir." |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 26 | DEFINE_string chrome_root_mount "/home/${SUDO_USER}/chrome_root" \ |
Sean Parent | 2898f75 | 2010-05-25 15:06:33 -0700 | [diff] [blame] | 27 | "The mount point of the chrome broswer source in the chroot." |
Brian Harring | 7b6f377 | 2012-09-23 14:01:13 -0700 | [diff] [blame] | 28 | DEFINE_string cache_dir "" "Directory to use for caching." |
Hidehiko Abe | 63d6c46 | 2017-03-02 17:40:54 +0900 | [diff] [blame] | 29 | DEFINE_string goma_dir "" "Goma installed directory." |
| 30 | DEFINE_string goma_client_json "" "Service account json file for goma." |
Yong Hong | 7dee2cc | 2018-02-06 16:02:56 +0800 | [diff] [blame] | 31 | DEFINE_string working_dir "" \ |
| 32 | "The working directory relative to ${CHROOT_TRUNK_DIR} for the command in \ |
| 33 | chroot, must start with '/' if set." |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 34 | |
Elly Jones | 7990a06 | 2010-09-02 09:23:23 -0400 | [diff] [blame] | 35 | DEFINE_boolean ssh_agent $FLAGS_TRUE "Import ssh agent." |
Brian Harring | 3576782 | 2012-02-01 23:50:45 -0800 | [diff] [blame] | 36 | DEFINE_boolean early_make_chroot $FLAGS_FALSE \ |
| 37 | "Internal flag. If set, the command is run as root without sudo." |
Don Garrett | ad3f059 | 2011-02-04 14:59:56 -0800 | [diff] [blame] | 38 | DEFINE_boolean verbose $FLAGS_FALSE "Print out actions taken" |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 39 | |
| 40 | # More useful help |
Doug Anderson | 9362fa8 | 2010-12-16 14:44:12 -0800 | [diff] [blame] | 41 | FLAGS_HELP="USAGE: $0 [flags] [VAR=value] [-- command [arg1] [arg2] ...] |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 42 | |
| 43 | One or more VAR=value pairs can be specified to export variables into |
| 44 | the chroot environment. For example: |
| 45 | |
| 46 | $0 FOO=bar BAZ=bel |
| 47 | |
Doug Anderson | 9362fa8 | 2010-12-16 14:44:12 -0800 | [diff] [blame] | 48 | If [-- command] is present, runs the command inside the chroot, |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 49 | after changing directory to /${SUDO_USER}/trunk/src/scripts. Note that neither |
Doug Anderson | 9362fa8 | 2010-12-16 14:44:12 -0800 | [diff] [blame] | 50 | the command nor args should include single quotes. For example: |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 51 | |
Doug Anderson | 9362fa8 | 2010-12-16 14:44:12 -0800 | [diff] [blame] | 52 | $0 -- ./build_platform_packages.sh |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 53 | |
| 54 | Otherwise, provides an interactive shell. |
| 55 | " |
| 56 | |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 57 | CROS_LOG_PREFIX=cros_sdk:enter_chroot |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 58 | SUDO_HOME=$(eval echo ~${SUDO_USER}) |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 59 | |
Don Garrett | ad3f059 | 2011-02-04 14:59:56 -0800 | [diff] [blame] | 60 | # Version of info from common.sh that only echos if --verbose is set. |
Mike Frysinger | 6b1abb2 | 2012-05-11 13:44:06 -0400 | [diff] [blame] | 61 | debug() { |
Don Garrett | ad3f059 | 2011-02-04 14:59:56 -0800 | [diff] [blame] | 62 | if [ $FLAGS_verbose -eq $FLAGS_TRUE ]; then |
David Rochberg | 351a76f | 2011-02-16 11:14:00 -0500 | [diff] [blame] | 63 | info "$*" |
Don Garrett | ad3f059 | 2011-02-04 14:59:56 -0800 | [diff] [blame] | 64 | fi |
| 65 | } |
| 66 | |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 67 | # Parse command line flags |
| 68 | FLAGS "$@" || exit 1 |
| 69 | eval set -- "${FLAGS_ARGV}" |
| 70 | |
Brian Harring | 7b6f377 | 2012-09-23 14:01:13 -0700 | [diff] [blame] | 71 | [ -z "${FLAGS_cache_dir}" ] && \ |
| 72 | die "--cache_dir is required" |
Brian Harring | 7ee892d | 2012-02-02 09:33:10 -0800 | [diff] [blame] | 73 | |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 74 | # Only now can we die on error. shflags functions leak non-zero error codes, |
Brian Harring | 7f175a5 | 2012-03-02 05:37:00 -0800 | [diff] [blame] | 75 | # so will die prematurely if 'switch_to_strict_mode' is specified before now. |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 76 | # TODO: replace shflags with something less error-prone, or contribute a fix. |
Brian Harring | 7f175a5 | 2012-03-02 05:37:00 -0800 | [diff] [blame] | 77 | switch_to_strict_mode |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 78 | |
Matt Tennant | 298f61a | 2012-06-25 21:54:33 -0700 | [diff] [blame] | 79 | # These config files are to be copied into chroot if they exist in home dir. |
Prathmesh Prabhu | 74ebbbd | 2015-03-17 13:50:29 -0700 | [diff] [blame] | 80 | # Additionally, git relevant files are copied by setup_git. |
Matt Tennant | 298f61a | 2012-06-25 21:54:33 -0700 | [diff] [blame] | 81 | FILES_TO_COPY_TO_CHROOT=( |
| 82 | .gdata_cred.txt # User/password for Google Docs on chromium.org |
| 83 | .gdata_token # Auth token for Google Docs on chromium.org |
Marc Herbert | 0c42206 | 2015-05-29 16:18:54 -0700 | [diff] [blame] | 84 | .inputrc # Preserve command line customizations |
Matt Tennant | 298f61a | 2012-06-25 21:54:33 -0700 | [diff] [blame] | 85 | ) |
Mike Frysinger | 270f405 | 2019-12-13 04:31:30 -0500 | [diff] [blame] | 86 | if [[ "${SUDO_USER:-${USER}}" == "chrome-bot" ]]; then |
Mike Frysinger | 6120545 | 2019-12-11 05:08:02 -0500 | [diff] [blame] | 87 | # Builders still haven't migrated fully to gitcookies. |
| 88 | # https://crbug.com/1032944 |
| 89 | FILES_TO_COPY_TO_CHROOT+=( .netrc ) |
| 90 | fi |
Matt Tennant | 298f61a | 2012-06-25 21:54:33 -0700 | [diff] [blame] | 91 | |
Sean Parent | 2898f75 | 2010-05-25 15:06:33 -0700 | [diff] [blame] | 92 | INNER_CHROME_ROOT=$FLAGS_chrome_root_mount # inside chroot |
Andrew de los Reyes | 6d0ca16 | 2010-02-12 14:36:08 -0800 | [diff] [blame] | 93 | CHROME_ROOT_CONFIG="/var/cache/chrome_root" # inside chroot |
Chris Sosa | aa1a7fd | 2010-04-02 14:06:29 -0700 | [diff] [blame] | 94 | FUSE_DEVICE="/dev/fuse" |
Andrew de los Reyes | 6d0ca16 | 2010-02-12 14:36:08 -0800 | [diff] [blame] | 95 | |
Mike Frysinger | 01c205d | 2013-03-22 00:59:58 -0400 | [diff] [blame] | 96 | # We can't use /var/lock because that might be a symlink to /run/lock outside |
| 97 | # of the chroot. Or /run on the host system might not exist. |
| 98 | LOCKFILE="${FLAGS_chroot}/.enter_chroot.lock" |
Mike Frysinger | 0a0e6ec | 2011-09-28 11:57:21 -0400 | [diff] [blame] | 99 | MOUNTED_PATH=$(readlink -f "$FLAGS_chroot") |
Mike Frysinger | 286b592 | 2011-09-28 11:59:53 -0400 | [diff] [blame] | 100 | |
Brian Harring | 2499bfb | 2012-12-18 16:23:31 -0800 | [diff] [blame] | 101 | # Reset the depot tools/internal trunk pathways to what they'll |
| 102 | # be w/in the chroot. |
| 103 | set_chroot_trunk_dir "${FLAGS_chroot}" |
| 104 | |
Mike Frysinger | eab3f07 | 2019-08-21 22:57:49 -0400 | [diff] [blame] | 105 | # Writes stdin to the given file name as the sudo user in overwrite mode. |
| 106 | # |
| 107 | # $@ - The output file names. |
| 108 | user_clobber() { |
| 109 | install -m644 -o ${SUDO_UID} -g ${SUDO_GID} /dev/stdin "$@" |
| 110 | } |
| 111 | |
| 112 | # Copies the specified file owned by the user to the specified location. |
| 113 | # If the copy fails as root (e.g. due to root_squash and NFS), retry the copy |
| 114 | # with the user's account before failing. |
| 115 | user_cp() { |
| 116 | cp -p "$@" 2>/dev/null || sudo -u ${SUDO_USER} -- cp -p "$@" |
| 117 | } |
| 118 | |
| 119 | # Appends stdin to the given file name as the sudo user. |
| 120 | # |
| 121 | # $1 - The output file name. |
| 122 | user_append() { |
| 123 | cat >> "$1" |
| 124 | chown ${SUDO_UID}:${SUDO_GID} "$1" |
| 125 | } |
| 126 | |
| 127 | # Create the specified directory, along with parents, as the sudo user. |
| 128 | # |
| 129 | # $@ - The directories to create. |
| 130 | user_mkdir() { |
| 131 | install -o ${SUDO_UID} -g ${SUDO_GID} -d "$@" |
| 132 | } |
| 133 | |
| 134 | # Create the specified symlink as the sudo user. |
| 135 | # |
| 136 | # $1 - Link target |
| 137 | # $2 - Link name |
| 138 | user_symlink() { |
| 139 | ln -sfT "$1" "$2" |
| 140 | chown -h ${SUDO_UID}:${SUDO_GID} "$2" |
| 141 | } |
Brian Harring | 2499bfb | 2012-12-18 16:23:31 -0800 | [diff] [blame] | 142 | |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 143 | setup_mount() { |
David Rochberg | 351a76f | 2011-02-16 11:14:00 -0500 | [diff] [blame] | 144 | # If necessary, mount $source in the host FS at $target inside the |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 145 | # chroot directory with $mount_args. We don't write to /etc/mtab because |
| 146 | # these mounts are all contained within an unshare and are therefore |
| 147 | # inaccessible to other namespaces (e.g. the host desktop system). |
David Rochberg | 351a76f | 2011-02-16 11:14:00 -0500 | [diff] [blame] | 148 | local source="$1" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 149 | local mount_args="-n $2" |
David Rochberg | 351a76f | 2011-02-16 11:14:00 -0500 | [diff] [blame] | 150 | local target="$3" |
| 151 | |
Mike Frysinger | 0a0e6ec | 2011-09-28 11:57:21 -0400 | [diff] [blame] | 152 | local mounted_path="${MOUNTED_PATH}$target" |
David Rochberg | 351a76f | 2011-02-16 11:14:00 -0500 | [diff] [blame] | 153 | |
Mike Frysinger | 9e5b0a4 | 2012-05-16 17:30:24 -0400 | [diff] [blame] | 154 | case " ${MOUNT_CACHE} " in |
| 155 | *" ${mounted_path} "*) |
Mike Frysinger | 2a97059 | 2011-09-20 22:49:01 -0400 | [diff] [blame] | 156 | # Already mounted! |
| 157 | ;; |
| 158 | *) |
Mike Frysinger | add9976 | 2014-03-27 13:17:58 -0400 | [diff] [blame] | 159 | # If it doesn't exist, assume they want a dir. But don't blindly run |
| 160 | # it all the time in case they're trying to bind mount a file. |
| 161 | if [[ ! -e ${mounted_path} ]]; then |
| 162 | mkdir -p "${mounted_path}" |
| 163 | fi |
Michael Krebs | 04c4f73 | 2012-09-07 18:31:46 -0700 | [diff] [blame] | 164 | # The args are left unquoted on purpose. |
| 165 | if [[ -n ${source} ]]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 166 | mount ${mount_args} "${source}" "${mounted_path}" |
Michael Krebs | 04c4f73 | 2012-09-07 18:31:46 -0700 | [diff] [blame] | 167 | else |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 168 | mount ${mount_args} "${mounted_path}" |
Michael Krebs | 04c4f73 | 2012-09-07 18:31:46 -0700 | [diff] [blame] | 169 | fi |
Mike Frysinger | 2a97059 | 2011-09-20 22:49:01 -0400 | [diff] [blame] | 170 | ;; |
| 171 | esac |
David Rochberg | 351a76f | 2011-02-16 11:14:00 -0500 | [diff] [blame] | 172 | } |
| 173 | |
Mike Frysinger | 6b1abb2 | 2012-05-11 13:44:06 -0400 | [diff] [blame] | 174 | copy_ssh_config() { |
Vadim Bendebury | 0779f52 | 2011-06-12 12:09:16 -0700 | [diff] [blame] | 175 | # Copy user .ssh/config into the chroot filtering out strings not supported |
| 176 | # by the chroot ssh. The chroot .ssh directory is passed in as the first |
| 177 | # parameter. |
| 178 | |
| 179 | # ssh options to filter out. The entire strings containing these substrings |
| 180 | # will be deleted before copying. |
| 181 | local bad_options=( |
Matt Tennant | 63c3cc5 | 2011-11-22 11:23:06 -0800 | [diff] [blame] | 182 | 'UseProxyIf' |
| 183 | 'GSSAPIAuthentication' |
| 184 | 'GSSAPIKeyExchange' |
| 185 | 'ProxyUseFdpass' |
Vadim Bendebury | 0779f52 | 2011-06-12 12:09:16 -0700 | [diff] [blame] | 186 | ) |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 187 | local sshc="${SUDO_HOME}/.ssh/config" |
Vadim Bendebury | 0779f52 | 2011-06-12 12:09:16 -0700 | [diff] [blame] | 188 | local chroot_ssh_dir="${1}" |
| 189 | local filter |
| 190 | local option |
| 191 | |
David James | 22dc2ba | 2012-11-29 15:46:58 -0800 | [diff] [blame] | 192 | if ! user_cp "${sshc}" "${chroot_ssh_dir}/config.orig" 2>/dev/null; then |
Vadim Bendebury | 0779f52 | 2011-06-12 12:09:16 -0700 | [diff] [blame] | 193 | return # Nothing to copy. |
| 194 | fi |
| 195 | |
| 196 | for option in "${bad_options[@]}" |
| 197 | do |
| 198 | if [ -z "${filter}" ]; then |
| 199 | filter="${option}" |
| 200 | else |
| 201 | filter+="\\|${option}" |
| 202 | fi |
| 203 | done |
| 204 | |
David James | 22dc2ba | 2012-11-29 15:46:58 -0800 | [diff] [blame] | 205 | sed "/^.*\(${filter}\).*$/d" "${chroot_ssh_dir}/config.orig" | \ |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 206 | user_clobber "${chroot_ssh_dir}/config" |
Vadim Bendebury | 0779f52 | 2011-06-12 12:09:16 -0700 | [diff] [blame] | 207 | } |
| 208 | |
Mike Frysinger | 6b1abb2 | 2012-05-11 13:44:06 -0400 | [diff] [blame] | 209 | copy_into_chroot_if_exists() { |
Matt Tennant | f7c9e77 | 2012-02-08 17:06:26 -0800 | [diff] [blame] | 210 | # $1 is file path outside of chroot to copy to path $2 inside chroot. |
Mike Frysinger | 6120545 | 2019-12-11 05:08:02 -0500 | [diff] [blame] | 211 | if [[ -e "$1" ]]; then |
Mike Frysinger | 0c4821f | 2019-12-15 19:35:43 -0500 | [diff] [blame^] | 212 | user_cp "$1" "${FLAGS_chroot}/$2" |
Mike Frysinger | 6120545 | 2019-12-11 05:08:02 -0500 | [diff] [blame] | 213 | fi |
Matt Tennant | f7c9e77 | 2012-02-08 17:06:26 -0800 | [diff] [blame] | 214 | } |
| 215 | |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 216 | # Usage: promote_api_keys |
| 217 | # This takes care of getting the developer API keys into the chroot where |
| 218 | # chrome can build with them. It needs to take it from the places a dev |
| 219 | # is likely to put them, and recognize that older chroots may or may not |
| 220 | # have been used since the concept of keys got added, as well as before |
Thiemo Nagel | 3a4d23b | 2017-05-26 16:52:05 +0200 | [diff] [blame] | 221 | # and after the developer deciding to grab their own keys. |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 222 | promote_api_keys() { |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 223 | local destination="${FLAGS_chroot}/home/${SUDO_USER}/.googleapikeys" |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 224 | # Don't disturb existing keys. They could be set differently |
| 225 | if [[ -s "${destination}" ]]; then |
| 226 | return 0 |
| 227 | fi |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 228 | if [[ -r "${SUDO_HOME}/.googleapikeys" ]]; then |
| 229 | cp -p "${SUDO_HOME}/.googleapikeys" "${destination}" |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 230 | if [[ -s "${destination}" ]] ; then |
| 231 | info "Copied Google API keys into chroot." |
| 232 | fi |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 233 | elif [[ -r "${SUDO_HOME}/.gyp/include.gypi" ]]; then |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 234 | local NAME="('google_(api_key|default_client_(id|secret))')" |
| 235 | local WS="[[:space:]]*" |
| 236 | local CONTENTS="('[^\\\\']*')" |
| 237 | sed -nr -e "/^${WS}${NAME}${WS}[:=]${WS}${CONTENTS}.*/{s//\1: \4,/;p;}" \ |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 238 | "${SUDO_HOME}/.gyp/include.gypi" | user_clobber "${destination}" |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 239 | if [[ -s "${destination}" ]]; then |
| 240 | info "Put discovered Google API keys into chroot." |
| 241 | fi |
| 242 | fi |
| 243 | } |
| 244 | |
Mike Frysinger | 4f2d5cc | 2013-06-09 23:34:52 -0400 | [diff] [blame] | 245 | generate_locales() { |
| 246 | # Make sure user's requested locales are available |
| 247 | # http://crosbug.com/19139 |
| 248 | # And make sure en_US{,.UTF-8} are always available as |
| 249 | # that what buildbot forces internally |
| 250 | local l locales gen_locales=() |
| 251 | |
| 252 | locales=$(printf '%s\n' en_US en_US.UTF-8 ${LANG} \ |
| 253 | $LC_{ADDRESS,ALL,COLLATE,CTYPE,IDENTIFICATION,MEASUREMENT,MESSAGES} \ |
| 254 | $LC_{MONETARY,NAME,NUMERIC,PAPER,TELEPHONE,TIME} | \ |
| 255 | sort -u | sed '/^C$/d') |
| 256 | for l in ${locales}; do |
| 257 | if [[ ${l} == *.* ]]; then |
| 258 | enc=${l#*.} |
| 259 | else |
| 260 | enc="ISO-8859-1" |
| 261 | fi |
| 262 | case $(echo ${enc//-} | tr '[:upper:]' '[:lower:]') in |
| 263 | utf8) enc="UTF-8";; |
| 264 | esac |
| 265 | gen_locales+=("${l} ${enc}") |
| 266 | done |
| 267 | if [[ ${#gen_locales[@]} -gt 0 ]] ; then |
| 268 | # Force LC_ALL=C to workaround slow string parsing in bash |
| 269 | # with long multibyte strings. Newer setups have this fixed, |
| 270 | # but locale-gen doesn't need to be run in any locale in the |
| 271 | # first place, so just go with C to keep it fast. |
Brian Norris | e83a147 | 2017-08-31 16:24:45 -0700 | [diff] [blame] | 272 | # Force jobs=1 to work around locale-gen weirdness where it simultaneously |
| 273 | # wants to and doesn't want to run multiple jobs (and complains about it). |
| 274 | # crbug.com/761153 |
Mike Frysinger | 4f2d5cc | 2013-06-09 23:34:52 -0400 | [diff] [blame] | 275 | chroot "${FLAGS_chroot}" env LC_ALL=C locale-gen -q -u \ |
Brian Norris | e83a147 | 2017-08-31 16:24:45 -0700 | [diff] [blame] | 276 | -j 1 -G "$(printf '%s\n' "${gen_locales[@]}")" |
Mike Frysinger | 4f2d5cc | 2013-06-09 23:34:52 -0400 | [diff] [blame] | 277 | fi |
| 278 | } |
| 279 | |
Mike Frysinger | 09c27c7 | 2019-12-10 18:44:39 -0500 | [diff] [blame] | 280 | git_config() { |
| 281 | USER="${SUDO_USER:-${USER}}" \ |
| 282 | HOME="${SUDO_HOME:-${HOME}}" \ |
| 283 | git config "$@" |
| 284 | } |
| 285 | |
Mike Frysinger | 2a67d48 | 2019-12-13 14:07:19 -0500 | [diff] [blame] | 286 | # The --type=path option is new to git-2.18 and not everyone upgrades. |
| 287 | # But not everyone uses the ~ prefix, so try that option if needed. |
| 288 | git_config_path() { |
| 289 | local out |
| 290 | out=$(git_config "$@") |
| 291 | if [[ "${out:0:1}" == "~" ]]; then |
| 292 | git_config --type path "$@" |
| 293 | else |
| 294 | echo "${out}" |
| 295 | fi |
| 296 | } |
| 297 | |
Prathmesh Prabhu | 74ebbbd | 2015-03-17 13:50:29 -0700 | [diff] [blame] | 298 | setup_git() { |
| 299 | # Copy .gitconfig into chroot so repo and git can be used from inside. |
| 300 | # This is required for repo to work since it validates the email address. |
| 301 | copy_into_chroot_if_exists "${SUDO_HOME}/.gitconfig" \ |
| 302 | "/home/${SUDO_USER}/.gitconfig" |
| 303 | local -r chroot_gitconfig="${FLAGS_chroot}/home/${SUDO_USER}/.gitconfig" |
| 304 | |
| 305 | # If the user didn't set up their username in their gitconfig, look |
| 306 | # at the default git settings for the user. |
| 307 | if ! git config -f "${chroot_gitconfig}" user.email >& /dev/null; then |
| 308 | local ident=$(cd /; sudo -u ${SUDO_USER} -- git var GIT_COMMITTER_IDENT || \ |
| 309 | :) |
| 310 | local ident_name=${ident%% <*} |
| 311 | local ident_email=${ident%%>*}; ident_email=${ident_email##*<} |
| 312 | git config -f "${chroot_gitconfig}" --replace-all user.name \ |
| 313 | "${ident_name}" || : |
| 314 | git config -f "${chroot_gitconfig}" --replace-all user.email \ |
| 315 | "${ident_email}" || : |
| 316 | fi |
| 317 | |
| 318 | # Copy the gitcookies file, updating the user's gitconfig to point to it. |
| 319 | local gitcookies |
Mike Frysinger | 2a67d48 | 2019-12-13 14:07:19 -0500 | [diff] [blame] | 320 | gitcookies="$(git_config_path --file "${chroot_gitconfig}" \ |
Mike Frysinger | 09c27c7 | 2019-12-10 18:44:39 -0500 | [diff] [blame] | 321 | --get http.cookiefile)" |
Prathmesh Prabhu | 74ebbbd | 2015-03-17 13:50:29 -0700 | [diff] [blame] | 322 | if [[ $? -ne 0 ]]; then |
| 323 | # Try the default location anyway. |
| 324 | gitcookies="${SUDO_HOME}/.gitcookies" |
| 325 | fi |
| 326 | copy_into_chroot_if_exists "${gitcookies}" "/home/${SUDO_USER}/.gitcookies" |
| 327 | local -r chroot_gitcookies="${FLAGS_chroot}/home/${SUDO_USER}/.gitcookies" |
| 328 | if [[ -e "${chroot_gitcookies}" ]]; then |
| 329 | git config -f "${chroot_gitconfig}" --replace-all http.cookiefile \ |
| 330 | "/home/${SUDO_USER}/.gitcookies" |
| 331 | fi |
| 332 | # This line must be at the end because using `git config` changes ownership of |
| 333 | # the .gitconfig. |
| 334 | chown ${SUDO_UID}:${SUDO_GID} "${chroot_gitconfig}" |
| 335 | } |
| 336 | |
Xiyuan Xia | a6e21ae | 2018-03-28 08:47:23 -0700 | [diff] [blame] | 337 | setup_gclient_cache_dir_mount() { |
| 338 | # Mount "cache_dir" if a glient checkout depends on it. |
| 339 | # Otherwise, git command inside chroot fails. See https://crbug.com/747349 |
| 340 | local checkout_root="$1" |
| 341 | |
| 342 | if [[ ! -e "${checkout_root}/.gclient" ]]; then |
| 343 | return 0 |
| 344 | fi |
| 345 | |
| 346 | local cache_dir=$(sed -n -E "s/^ *cache_dir *= *'(.*)'/\1/p" \ |
| 347 | "${checkout_root}/.gclient") |
| 348 | if [[ -z "${cache_dir}" ]]; then |
| 349 | return 0 |
| 350 | fi |
| 351 | |
Mike Frysinger | d5a3e6d | 2019-08-07 15:23:15 -0400 | [diff] [blame] | 352 | # See if the cache dir exists outside of the chroot. |
Xiyuan Xia | a6e21ae | 2018-03-28 08:47:23 -0700 | [diff] [blame] | 353 | if [[ ! -d "${cache_dir}" ]]; then |
Mike Frysinger | d5a3e6d | 2019-08-07 15:23:15 -0400 | [diff] [blame] | 354 | # See if it exists inside the chroot (which can happen if the checkout was |
| 355 | # created in there). |
| 356 | if [[ ! -d "${FLAGS_chroot}/${cache_dir}" ]]; then |
| 357 | warn "Gclient cache dir \"${cache_dir}\" is not a directory." |
| 358 | fi |
Xiyuan Xia | a6e21ae | 2018-03-28 08:47:23 -0700 | [diff] [blame] | 359 | return 0 |
| 360 | fi |
| 361 | |
| 362 | setup_mount "${cache_dir}" "--bind" "${cache_dir}" |
| 363 | } |
| 364 | |
Mike Frysinger | 6b1abb2 | 2012-05-11 13:44:06 -0400 | [diff] [blame] | 365 | setup_env() { |
Andrew de los Reyes | c9317ea | 2010-02-10 13:16:36 -0800 | [diff] [blame] | 366 | ( |
| 367 | flock 200 |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 368 | |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 369 | # Make the lockfile writable for backwards compatibility. |
| 370 | chown ${SUDO_UID}:${SUDO_GID} "${LOCKFILE}" |
| 371 | |
| 372 | # Refresh /etc/resolv.conf and /etc/hosts in the chroot. |
| 373 | install -C -m644 /etc/resolv.conf ${FLAGS_chroot}/etc/resolv.conf |
| 374 | install -C -m644 /etc/hosts ${FLAGS_chroot}/etc/hosts |
David James | 412b902 | 2011-07-15 19:54:16 -0700 | [diff] [blame] | 375 | |
Don Garrett | a0e7ea1 | 2011-02-07 18:39:59 -0800 | [diff] [blame] | 376 | debug "Mounting chroot environment." |
Steev Klimaszewski | a10974c | 2013-11-30 20:38:34 -0600 | [diff] [blame] | 377 | mount --make-rslave / |
Benjamin Gordon | 1d5afed | 2017-06-14 16:35:32 -0600 | [diff] [blame] | 378 | if grep -q -e "${FLAGS_chroot}[[:space:]]" /proc/mounts; then |
| 379 | debug "Changing $FLAGS_chroot to a private subtree." |
| 380 | mount --make-private "$FLAGS_chroot" |
| 381 | fi |
Mike Frysinger | 9e5b0a4 | 2012-05-16 17:30:24 -0400 | [diff] [blame] | 382 | MOUNT_CACHE=$(echo $(awk '{print $2}' /proc/mounts)) |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 383 | setup_mount none "-t proc" /proc |
| 384 | setup_mount none "-t sysfs" /sys |
Gaurav Shah | 365b706 | 2013-12-03 18:12:58 -0800 | [diff] [blame] | 385 | if grep -q binfmt_misc /proc/filesystems; then |
| 386 | setup_mount binfmt_misc "-t binfmt_misc" /proc/sys/fs/binfmt_misc |
| 387 | fi |
Victor Dodon | c34d4bc | 2016-05-09 12:09:21 -0700 | [diff] [blame] | 388 | if grep -q configfs /proc/filesystems; then |
| 389 | setup_mount none "-t configfs" /sys/kernel/config |
| 390 | fi |
Mike Frysinger | b5080fb | 2019-03-19 04:13:02 -0400 | [diff] [blame] | 391 | setup_mount /dev "--rbind" /dev |
David James | 482fb29 | 2013-03-10 21:06:54 -0700 | [diff] [blame] | 392 | if [[ -d /run ]]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 393 | setup_mount /run "--bind" /run |
David James | 482fb29 | 2013-03-10 21:06:54 -0700 | [diff] [blame] | 394 | if [[ -d /run/shm && ! -L /run/shm ]]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 395 | setup_mount /run/shm "--bind" /run/shm |
Aaron Plattner | 130d363 | 2011-10-18 08:54:57 -0700 | [diff] [blame] | 396 | fi |
| 397 | fi |
Brian Harring | 2499bfb | 2012-12-18 16:23:31 -0800 | [diff] [blame] | 398 | |
Mike Frysinger | 4f2d5cc | 2013-06-09 23:34:52 -0400 | [diff] [blame] | 399 | # Do this early as it's slow and only needs basic mounts (above). |
| 400 | generate_locales & |
| 401 | |
Michael Spang | 15144f4 | 2013-04-02 17:42:55 -0400 | [diff] [blame] | 402 | setup_mount "${FLAGS_trunk}" "--rbind" "${CHROOT_TRUNK_DIR}" |
Chris Sosa | 389634d | 2012-09-05 19:56:53 -0700 | [diff] [blame] | 403 | |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 404 | debug "Setting up referenced repositories if required." |
Mike Frysinger | 2a67d48 | 2019-12-13 14:07:19 -0500 | [diff] [blame] | 405 | REFERENCE_DIR=$(git_config_path --file \ |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 406 | "${FLAGS_trunk}/.repo/manifests.git/config" \ |
| 407 | repo.reference) |
| 408 | if [ -n "${REFERENCE_DIR}" ]; then |
| 409 | |
Brian Harring | 334050f | 2012-06-08 17:40:58 -0700 | [diff] [blame] | 410 | ALTERNATES="${FLAGS_trunk}/.repo/alternates" |
| 411 | |
| 412 | # Ensure this directory exists ourselves, and has the correct ownership. |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 413 | user_mkdir "${ALTERNATES}" |
Brian Harring | 334050f | 2012-06-08 17:40:58 -0700 | [diff] [blame] | 414 | |
| 415 | unset ALTERNATES |
| 416 | |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 417 | IFS=$'\n'; |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 418 | required=( $( sudo -u "${SUDO_USER}" -- \ |
Mike Frysinger | 1658c3e | 2019-08-21 20:24:02 -0400 | [diff] [blame] | 419 | "${FLAGS_trunk}/chromite/lib/rewrite_git_alternates" \ |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 420 | "${FLAGS_trunk}" "${REFERENCE_DIR}" "${CHROOT_TRUNK_DIR}" ) ) |
| 421 | unset IFS |
| 422 | |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 423 | setup_mount "${FLAGS_trunk}/.repo/chroot/alternates" --bind \ |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 424 | "${CHROOT_TRUNK_DIR}/.repo/alternates" |
| 425 | |
| 426 | # Note that as we're bringing up each referened repo, we also |
| 427 | # mount bind an empty directory over its alternates. This is |
| 428 | # required to suppress git from tracing through it- we already |
| 429 | # specify the required alternates for CHROOT_TRUNK_DIR, no point |
| 430 | # in having git try recursing through each on their own. |
| 431 | # |
| 432 | # Finally note that if you're unfamiliar w/ chroot/vfs semantics, |
| 433 | # the bind is visible only w/in the chroot. |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 434 | user_mkdir ${FLAGS_trunk}/.repo/chroot/empty |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 435 | position=1 |
| 436 | for x in "${required[@]}"; do |
| 437 | base="${CHROOT_TRUNK_DIR}/.repo/chroot/external${position}" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 438 | setup_mount "${x}" "--bind" "${base}" |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 439 | if [ -e "${x}/.repo/alternates" ]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 440 | setup_mount "${FLAGS_trunk}/.repo/chroot/empty" "--bind" \ |
Brian Harring | dd7d793 | 2011-12-23 04:21:33 -0800 | [diff] [blame] | 441 | "${base}/.repo/alternates" |
| 442 | fi |
| 443 | position=$(( ${position} + 1 )) |
| 444 | done |
| 445 | unset required position base |
| 446 | fi |
| 447 | unset REFERENCE_DIR |
| 448 | |
Brian Harring | 7b6f377 | 2012-09-23 14:01:13 -0700 | [diff] [blame] | 449 | chroot_cache='/var/cache/chromeos-cache' |
| 450 | debug "Setting up shared cache dir directory." |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 451 | user_mkdir "${FLAGS_cache_dir}"/distfiles/{target,host} |
| 452 | user_mkdir "${FLAGS_chroot}/${chroot_cache}" |
| 453 | setup_mount "${FLAGS_cache_dir}" "--bind" "${chroot_cache}" |
Brian Harring | 7b6f377 | 2012-09-23 14:01:13 -0700 | [diff] [blame] | 454 | # TODO(build): remove this as of 12/01/12. |
| 455 | # Because of how distfiles -> cache_dir was deployed, if this isn't |
| 456 | # a symlink, we *know* the ondisk pathways aren't compatible- thus |
| 457 | # fix it now. |
| 458 | distfiles_path="${FLAGS_chroot}/var/cache/distfiles" |
| 459 | if [ ! -L "${distfiles_path}" ]; then |
| 460 | # While we're at it, ensure the var is exported w/in the chroot; it |
| 461 | # won't exist if distfiles isn't a symlink. |
Paul Drews | b688cbe | 2012-10-08 15:33:43 -0700 | [diff] [blame] | 462 | p="${FLAGS_chroot}/etc/profile.d/chromeos-cachedir.sh" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 463 | rm -rf "${distfiles_path}" |
| 464 | ln -s chromeos-cache/distfiles "${distfiles_path}" |
| 465 | mkdir -p -m 775 "${p%/*}" |
| 466 | echo 'export CHROMEOS_CACHEDIR=${chroot_cache}' > "${p}" |
| 467 | chmod 0644 "${p}" |
Brian Harring | 7b6f377 | 2012-09-23 14:01:13 -0700 | [diff] [blame] | 468 | fi |
Brian Harring | 7ee892d | 2012-02-02 09:33:10 -0800 | [diff] [blame] | 469 | |
Aviv Keshet | 97a35f4 | 2014-07-24 12:11:10 -0700 | [diff] [blame] | 470 | if [ -d "${SUDO_HOME}/.cidb_creds" ]; then |
| 471 | setup_mount "${SUDO_HOME}/.cidb_creds" --bind \ |
| 472 | "/home/${SUDO_USER}/.cidb_creds" |
| 473 | fi |
| 474 | |
Elly Jones | 7990a06 | 2010-09-02 09:23:23 -0400 | [diff] [blame] | 475 | if [ $FLAGS_ssh_agent -eq $FLAGS_TRUE ]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 476 | if [ -n "${SSH_AUTH_SOCK}" -a -d "${SUDO_HOME}/.ssh" ]; then |
Mike Frysinger | add9976 | 2014-03-27 13:17:58 -0400 | [diff] [blame] | 477 | local target_ssh="/home/${SUDO_USER}/.ssh" |
| 478 | TARGET_DIR="${FLAGS_chroot}${target_ssh}" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 479 | user_mkdir "${TARGET_DIR}" |
Mike Frysinger | add9976 | 2014-03-27 13:17:58 -0400 | [diff] [blame] | 480 | |
| 481 | local known_hosts="${SUDO_HOME}/.ssh/known_hosts" |
| 482 | if [[ -e ${known_hosts} ]]; then |
| 483 | truncate -s 0 "${TARGET_DIR}/known_hosts" |
| 484 | setup_mount "${known_hosts}" --bind "${target_ssh}/known_hosts" |
| 485 | fi |
David James | 22dc2ba | 2012-11-29 15:46:58 -0800 | [diff] [blame] | 486 | ( |
Mike Frysinger | add9976 | 2014-03-27 13:17:58 -0400 | [diff] [blame] | 487 | # Only copy ~/.ssh/*.pub if they exist. Since we set |
David James | 22dc2ba | 2012-11-29 15:46:58 -0800 | [diff] [blame] | 488 | # nullglob, this needs to happen within a subshell. |
| 489 | shopt -s nullglob |
Mike Frysinger | add9976 | 2014-03-27 13:17:58 -0400 | [diff] [blame] | 490 | files=("${SUDO_HOME}"/.ssh/*.pub) |
David James | 22dc2ba | 2012-11-29 15:46:58 -0800 | [diff] [blame] | 491 | if [[ ${#files[@]} -gt 0 ]]; then |
| 492 | user_cp "${files[@]}" "${TARGET_DIR}/" |
| 493 | fi |
| 494 | ) |
Vadim Bendebury | 0779f52 | 2011-06-12 12:09:16 -0700 | [diff] [blame] | 495 | copy_ssh_config "${TARGET_DIR}" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 496 | chown -R ${SUDO_UID}:${SUDO_GID} "${TARGET_DIR}" |
Mike Frysinger | 9de707f | 2011-12-12 14:21:44 -0500 | [diff] [blame] | 497 | |
Kevin Cernekee | a171839 | 2016-10-16 19:54:57 -0700 | [diff] [blame] | 498 | if [ -S "${SSH_AUTH_SOCK}" ]; then |
| 499 | touch "${FLAGS_chroot}/tmp/ssh-auth-sock" |
| 500 | setup_mount "${SSH_AUTH_SOCK}" "--bind" "/tmp/ssh-auth-sock" |
Mike Frysinger | 9de707f | 2011-12-12 14:21:44 -0500 | [diff] [blame] | 501 | fi |
Elly Jones | 7990a06 | 2010-09-02 09:23:23 -0400 | [diff] [blame] | 502 | fi |
| 503 | fi |
| 504 | |
Marc MERLIN | fcd84ef | 2013-03-07 14:34:43 -0800 | [diff] [blame] | 505 | if [[ -d "$SUDO_HOME/.subversion" ]]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 506 | TARGET="/home/${SUDO_USER}/.subversion" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 507 | setup_mount "${SUDO_HOME}/.subversion" "--bind" "${TARGET}" |
Paul Drews | b4605b4 | 2012-10-11 23:10:43 -0700 | [diff] [blame] | 508 | # Symbolic-link the .subversion directory so sandboxed subversion.class |
| 509 | # clients can use it. |
Paul Drews | b4605b4 | 2012-10-11 23:10:43 -0700 | [diff] [blame] | 510 | for d in \ |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 511 | "${FLAGS_cache_dir}"/distfiles/{host,target}/svn-src/"${SUDO_USER}"; do |
Paul Drews | b4605b4 | 2012-10-11 23:10:43 -0700 | [diff] [blame] | 512 | if [[ ! -L "${d}/.subversion" ]]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 513 | rm -rf "${d}/.subversion" |
| 514 | user_mkdir "${d}" |
| 515 | user_symlink /home/${SUDO_USER}/.subversion "${d}/.subversion" |
Paul Drews | b4605b4 | 2012-10-11 23:10:43 -0700 | [diff] [blame] | 516 | fi |
| 517 | done |
Mike Frysinger | 286b592 | 2011-09-28 11:59:53 -0400 | [diff] [blame] | 518 | fi |
| 519 | |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 520 | # A reference to the DEPOT_TOOLS path may be passed in by cros_sdk. |
| 521 | if [ -n "${DEPOT_TOOLS}" ]; then |
Mike Frysinger | 286b592 | 2011-09-28 11:59:53 -0400 | [diff] [blame] | 522 | debug "Mounting depot_tools" |
Brian Harring | 2499bfb | 2012-12-18 16:23:31 -0800 | [diff] [blame] | 523 | setup_mount "${DEPOT_TOOLS}" --bind "${DEPOT_TOOLS_DIR}" |
Mike Frysinger | 286b592 | 2011-09-28 11:59:53 -0400 | [diff] [blame] | 524 | fi |
| 525 | |
Hidehiko Abe | 63d6c46 | 2017-03-02 17:40:54 +0900 | [diff] [blame] | 526 | if [[ -n "${FLAGS_goma_dir}" ]]; then |
| 527 | debug "Mounting goma" |
| 528 | # $HOME/goma is the default directory for goma. |
| 529 | # It is used by goma if GOMA_DIR is not provide. |
| 530 | setup_mount "${FLAGS_goma_dir}" --bind "/home/${SUDO_USER}/goma" |
| 531 | fi |
| 532 | |
| 533 | if [[ -n "${FLAGS_goma_client_json}" ]]; then |
| 534 | debug "Mounting service-account-goma-client.json" |
| 535 | local dest_path="/creds/service_accounts/service-account-goma-client.json" |
| 536 | # setup_mount assumes the target is a directory by default. |
| 537 | # So here, touch the file in advance. |
| 538 | local mounted_path="${MOUNTED_PATH}${dest_path}" |
Hidehiko Abe | 053a199 | 2017-03-07 16:44:18 +0900 | [diff] [blame] | 539 | mkdir -p "$(dirname "${mounted_path}")" |
Hidehiko Abe | 63d6c46 | 2017-03-02 17:40:54 +0900 | [diff] [blame] | 540 | touch "${mounted_path}" |
Hidehiko Abe | 053a199 | 2017-03-07 16:44:18 +0900 | [diff] [blame] | 541 | # Note: Original UID:GID and permission should be inherited even after |
Hidehiko Abe | 63d6c46 | 2017-03-02 17:40:54 +0900 | [diff] [blame] | 542 | # mounting. |
| 543 | setup_mount "${FLAGS_goma_client_json}" --bind "${dest_path}" |
| 544 | fi |
| 545 | |
Michael Krebs | 04c4f73 | 2012-09-07 18:31:46 -0700 | [diff] [blame] | 546 | # Mount additional directories as specified in .local_mounts file. |
| 547 | local local_mounts="${FLAGS_trunk}/src/scripts/.local_mounts" |
| 548 | if [[ -f ${local_mounts} ]]; then |
Gaurav Shah | e3cffca | 2013-11-26 14:45:10 -0800 | [diff] [blame] | 549 | info "Mounting local folders" |
Michael Krebs | 04c4f73 | 2012-09-07 18:31:46 -0700 | [diff] [blame] | 550 | # format: mount_source |
| 551 | # or mount_source mount_point |
| 552 | # or # comments |
| 553 | local mount_source mount_point |
| 554 | while read mount_source mount_point; do |
| 555 | if [[ -z ${mount_source} ]]; then |
| 556 | continue |
| 557 | fi |
| 558 | # if only source is assigned, use source as mount point. |
| 559 | : ${mount_point:=${mount_source}} |
| 560 | debug " mounting ${mount_source} on ${mount_point}" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 561 | setup_mount "${mount_source}" "--bind" "${mount_point}" |
Michael Krebs | 04c4f73 | 2012-09-07 18:31:46 -0700 | [diff] [blame] | 562 | done < <(sed -e 's:#.*::' "${local_mounts}") |
| 563 | fi |
| 564 | |
Mike Frysinger | 9a50b64 | 2011-09-20 23:37:14 -0400 | [diff] [blame] | 565 | CHROME_ROOT="$(readlink -f "$FLAGS_chrome_root" || :)" |
| 566 | if [ -z "$CHROME_ROOT" ]; then |
| 567 | CHROME_ROOT="$(cat "${FLAGS_chroot}${CHROME_ROOT_CONFIG}" \ |
| 568 | 2>/dev/null || :)" |
| 569 | CHROME_ROOT_AUTO=1 |
| 570 | fi |
| 571 | if [[ -n "$CHROME_ROOT" ]]; then |
| 572 | if [[ ! -d "${CHROME_ROOT}/src" ]]; then |
Mike Frysinger | 9d73a85 | 2013-12-02 19:47:08 -0500 | [diff] [blame] | 573 | error "Not mounting chrome source: could not find CHROME_ROOT/src dir." |
| 574 | error "Full path we tried: ${CHROME_ROOT}/src" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 575 | rm -f "${FLAGS_chroot}${CHROME_ROOT_CONFIG}" |
Mike Frysinger | 9a50b64 | 2011-09-20 23:37:14 -0400 | [diff] [blame] | 576 | if [[ ! "$CHROME_ROOT_AUTO" ]]; then |
| 577 | exit 1 |
Don Garrett | a0e7ea1 | 2011-02-07 18:39:59 -0800 | [diff] [blame] | 578 | fi |
Mike Frysinger | 9a50b64 | 2011-09-20 23:37:14 -0400 | [diff] [blame] | 579 | else |
| 580 | debug "Mounting chrome source at: $INNER_CHROME_ROOT" |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 581 | echo $CHROME_ROOT > "${FLAGS_chroot}${CHROME_ROOT_CONFIG}" |
| 582 | setup_mount "$CHROME_ROOT" --bind "$INNER_CHROME_ROOT" |
Xiyuan Xia | a6e21ae | 2018-03-28 08:47:23 -0700 | [diff] [blame] | 583 | setup_gclient_cache_dir_mount "$CHROME_ROOT" |
Andrew de los Reyes | 6d0ca16 | 2010-02-12 14:36:08 -0800 | [diff] [blame] | 584 | fi |
| 585 | fi |
Andrew de los Reyes | 5d0248f | 2010-02-12 16:12:31 -0800 | [diff] [blame] | 586 | |
Mike Frysinger | acc4c9b | 2011-09-15 18:06:25 -0400 | [diff] [blame] | 587 | # Install fuse module. Skip modprobe when possible for slight |
| 588 | # speed increase when initializing the env. |
| 589 | if [ -c "${FUSE_DEVICE}" ] && ! grep -q fuse /proc/filesystems; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 590 | modprobe fuse 2> /dev/null ||\ |
Sean O | cd8b1d1 | 2010-09-02 17:34:49 +0200 | [diff] [blame] | 591 | warn "-- Note: modprobe fuse failed. gmergefs will not work" |
Chris Sosa | 317d8eb | 2010-04-05 15:45:28 -0700 | [diff] [blame] | 592 | fi |
| 593 | |
Mike Frysinger | 926a4b9 | 2012-06-27 15:22:28 -0400 | [diff] [blame] | 594 | # Fix permissions on ccache tree. If this is a fresh chroot, then they |
| 595 | # might not be set up yet. Or if the user manually `rm -rf`-ed things, |
| 596 | # we need to reset it. Otherwise, gcc itself takes care of fixing things |
| 597 | # on demand, but only when it updates. |
| 598 | ccache_dir="${FLAGS_chroot}/var/cache/distfiles/ccache" |
| 599 | if [[ ! -d ${ccache_dir} ]]; then |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 600 | mkdir -p -m 2775 "${ccache_dir}" |
Mike Frysinger | 926a4b9 | 2012-06-27 15:22:28 -0400 | [diff] [blame] | 601 | fi |
Mike Frysinger | ba60991 | 2015-05-20 00:44:25 -0400 | [diff] [blame] | 602 | ( |
| 603 | find -H "${ccache_dir}" '(' -type d -a '!' -perm 2775 ')' \ |
| 604 | -exec chmod 2775 {} + |
| 605 | find -H "${ccache_dir}" -gid 0 -exec chgrp 250 {} + |
| 606 | # These settings are kept in sync with the gcc ebuild. |
| 607 | chroot "${FLAGS_chroot}" env CCACHE_DIR=/var/cache/distfiles/ccache \ |
| 608 | CCACHE_UMASK=002 ccache -F 0 -M 11G >/dev/null |
| 609 | ) & |
David James | 342f156 | 2011-07-15 15:21:18 -0700 | [diff] [blame] | 610 | |
Matt Tennant | 298f61a | 2012-06-25 21:54:33 -0700 | [diff] [blame] | 611 | # Certain files get copied into the chroot when entering. |
| 612 | for fn in "${FILES_TO_COPY_TO_CHROOT[@]}"; do |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 613 | copy_into_chroot_if_exists "${SUDO_HOME}/${fn}" "/home/${SUDO_USER}/${fn}" |
Matt Tennant | f7c9e77 | 2012-02-08 17:06:26 -0800 | [diff] [blame] | 614 | done |
Prathmesh Prabhu | 74ebbbd | 2015-03-17 13:50:29 -0700 | [diff] [blame] | 615 | setup_git |
Peter Mayo | 4411efe | 2012-09-21 04:41:27 -0400 | [diff] [blame] | 616 | promote_api_keys |
Matt Tennant | d4316fe | 2011-08-30 12:06:42 -0700 | [diff] [blame] | 617 | |
Dale Curtis | 9863173 | 2011-05-05 16:16:59 -0700 | [diff] [blame] | 618 | # Fix permissions on shared memory to allow non-root users access to POSIX |
Josh McSavaney | 8477dad | 2016-04-05 13:43:26 -0700 | [diff] [blame] | 619 | # semaphores. Take special care to only change the permissions on the |
| 620 | # directory and not all of its contents. |
| 621 | chmod 1777 "${FLAGS_chroot}/dev/shm" |
Chris Wolfe | 916b1f1 | 2012-04-30 16:03:06 -0400 | [diff] [blame] | 622 | |
Yu-Ju Hong | 22278a2 | 2014-01-16 12:46:53 -0800 | [diff] [blame] | 623 | # gsutil uses boto config to store settings and credentials. Copy |
| 624 | # user's own boto file into the chroot if it exists. Also copy it |
| 625 | # to /root for sudoed invocations. |
| 626 | chroot_user_boto="${FLAGS_chroot}/home/${SUDO_USER}/.boto" |
| 627 | chroot_root_boto="${FLAGS_chroot}/root/.boto" |
| 628 | if [ -f ${SUDO_HOME}/.boto ]; then |
| 629 | # Pass --remote-destination to overwrite a symlink. |
| 630 | user_cp "--remove-destination" "${SUDO_HOME}/.boto" "$chroot_user_boto" |
Frank Henigman | 696ce08 | 2014-03-27 21:21:55 -0400 | [diff] [blame] | 631 | cp "--remove-destination" "$chroot_user_boto" "$chroot_root_boto" |
David Riley | b6e9d86 | 2016-02-25 16:58:02 -0800 | [diff] [blame] | 632 | elif [ -f "/etc/boto.cfg" ]; then |
| 633 | # For GCE instances, the non-chroot .boto file is not deployed so |
| 634 | # use the system /etc/boto.cfg if it exists. |
| 635 | user_cp "--remove-destination" "/etc/boto.cfg" "$chroot_user_boto" |
| 636 | cp "--remove-destination" "$chroot_user_boto" "$chroot_root_boto" |
Yu-Ju Hong | 22278a2 | 2014-01-16 12:46:53 -0800 | [diff] [blame] | 637 | fi |
| 638 | |
| 639 | # If user doesn't have a boto file, check if the private overlays |
| 640 | # are installed and use those credentials. |
Gilad Arnold | 264f64d | 2012-09-06 14:01:45 -0700 | [diff] [blame] | 641 | boto='src/private-overlays/chromeos-overlay/googlestorage_account.boto' |
| 642 | if [ -s "${FLAGS_trunk}/${boto}" ]; then |
Yu-Ju Hong | 22278a2 | 2014-01-16 12:46:53 -0800 | [diff] [blame] | 643 | if [ ! -e "$chroot_user_boto" ]; then |
| 644 | user_symlink "trunk/${boto}" "$chroot_user_boto" |
Chris Wolfe | 916b1f1 | 2012-04-30 16:03:06 -0400 | [diff] [blame] | 645 | fi |
Yu-Ju Hong | 22278a2 | 2014-01-16 12:46:53 -0800 | [diff] [blame] | 646 | if [ ! -e "$chroot_root_boto" ]; then |
| 647 | ln -sf "${CHROOT_TRUNK_DIR}/${boto}" "$chroot_root_boto" |
Gilad Arnold | 264f64d | 2012-09-06 14:01:45 -0700 | [diff] [blame] | 648 | fi |
Chris Wolfe | 916b1f1 | 2012-04-30 16:03:06 -0400 | [diff] [blame] | 649 | fi |
| 650 | |
| 651 | # Have found a few chroots where ~/.gsutil is owned by root:root, probably |
| 652 | # as a result of old gsutil or tools. This causes permission errors when |
| 653 | # gsutil cp tries to create its cache files, so ensure the user can |
| 654 | # actually write to their directory. |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 655 | gsutil_dir="${FLAGS_chroot}/home/${SUDO_USER}/.gsutil" |
| 656 | if [ -d "${gsutil_dir}" ]; then |
| 657 | chown -R ${SUDO_UID}:${SUDO_GID} "${gsutil_dir}" |
Chris Wolfe | 916b1f1 | 2012-04-30 16:03:06 -0400 | [diff] [blame] | 658 | fi |
David James | 546747b | 2010-03-23 15:19:43 -0700 | [diff] [blame] | 659 | ) 200>>"$LOCKFILE" || die "setup_env failed" |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 660 | } |
| 661 | |
rspangler@google.com | d74220d | 2009-10-09 20:56:14 +0000 | [diff] [blame] | 662 | setup_env |
| 663 | |
Brian Harring | 3576782 | 2012-02-01 23:50:45 -0800 | [diff] [blame] | 664 | CHROOT_PASSTHRU=( |
| 665 | "BUILDBOT_BUILD=$FLAGS_build_number" |
Brian Harring | 3576782 | 2012-02-01 23:50:45 -0800 | [diff] [blame] | 666 | "CHROMEOS_RELEASE_APPID=${CHROMEOS_RELEASE_APPID:-{DEV-BUILD}}" |
Brian Harring | 3576782 | 2012-02-01 23:50:45 -0800 | [diff] [blame] | 667 | "EXTERNAL_TRUNK_PATH=${FLAGS_trunk}" |
Yong Hong | 7dee2cc | 2018-02-06 16:02:56 +0800 | [diff] [blame] | 668 | |
| 669 | # The default ~/.bash_profile in chroot will cd to $CHROOT_CWD instead of |
| 670 | # ~/trunk/src/script if that environment variable is set. |
| 671 | "CHROOT_CWD=${FLAGS_working_dir}" |
Brian Harring | 3576782 | 2012-02-01 23:50:45 -0800 | [diff] [blame] | 672 | ) |
Liam McLoughlin | 3b11b45 | 2011-03-14 16:04:07 -0700 | [diff] [blame] | 673 | |
Josh Triplett | d6a13bf | 2014-06-13 15:36:52 -0700 | [diff] [blame] | 674 | # Translate C.UTF-8 into something we support. Remove this when our glibc |
| 675 | # starts supporting C.UTF-8. https://bugzilla.redhat.com/show_bug.cgi?id=902094 |
| 676 | for var in LANG \ |
| 677 | LC_{ADDRESS,ALL,COLLATE,CTYPE,IDENTIFICATION,MEASUREMENT,MESSAGES} \ |
| 678 | LC_{MONETARY,NAME,NUMERIC,PAPER,TELEPHONE,TIME}; do |
| 679 | if [[ ${!var} =~ C\.[Uu][Tt][Ff]-?8 ]]; then |
| 680 | if [[ ${var} == LC_COLLATE ]]; then |
| 681 | export LC_COLLATE=C |
| 682 | else |
| 683 | export ${var}=en_US.UTF-8 |
| 684 | fi |
| 685 | fi |
| 686 | done |
| 687 | |
Kevin Cernekee | a171839 | 2016-10-16 19:54:57 -0700 | [diff] [blame] | 688 | # Needs to be set here because setup_env runs in a subshell. |
| 689 | [ -S "${FLAGS_chroot}/tmp/ssh-auth-sock" ] && SSH_AUTH_SOCK=/tmp/ssh-auth-sock |
| 690 | |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 691 | # Add the whitelisted environment variables to CHROOT_PASSTHRU. |
| 692 | load_environment_whitelist |
| 693 | for var in "${ENVIRONMENT_WHITELIST[@]}" ; do |
Brian Harring | 06d3c2e | 2012-08-23 07:35:43 -0700 | [diff] [blame] | 694 | [ "${!var+set}" = "set" ] && CHROOT_PASSTHRU+=( "${var}=${!var}" ) |
Mario Limonciello | 7052ae1 | 2011-05-05 12:00:49 -0500 | [diff] [blame] | 695 | done |
| 696 | |
Paul Drews | 67d9ef1 | 2013-03-20 08:47:47 -0700 | [diff] [blame] | 697 | # Set up GIT_PROXY_COMMAND so git:// URLs automatically work behind a proxy. |
| 698 | if [[ -n "${all_proxy}" || -n "${https_proxy}" || -n "${http_proxy}" ]]; then |
| 699 | CHROOT_PASSTHRU+=( |
| 700 | "GIT_PROXY_COMMAND=${CHROOT_TRUNK_DIR}/src/scripts/bin/proxy-gw" |
| 701 | ) |
| 702 | fi |
| 703 | |
derat@google.com | 4e7a92b | 2009-11-21 23:44:14 +0000 | [diff] [blame] | 704 | # Run command or interactive shell. Also include the non-chrooted path to |
| 705 | # the source trunk for scripts that may need to print it (e.g. |
| 706 | # build_image.sh). |
Brian Harring | 3576782 | 2012-02-01 23:50:45 -0800 | [diff] [blame] | 707 | |
| 708 | if [ $FLAGS_early_make_chroot -eq $FLAGS_TRUE ]; then |
| 709 | cmd=( /bin/bash -l -c 'env "$@"' -- ) |
| 710 | elif [ ! -x "${FLAGS_chroot}/usr/bin/sudo" ]; then |
| 711 | # Complain that sudo is missing. |
| 712 | error "Failing since the chroot lacks sudo." |
| 713 | error "Requested enter_chroot command was: $@" |
| 714 | exit 127 |
| 715 | else |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 716 | cmd=( sudo -i -u "${SUDO_USER}" ) |
Brian Harring | 3576782 | 2012-02-01 23:50:45 -0800 | [diff] [blame] | 717 | fi |
| 718 | |
David James | 7676488 | 2012-10-24 19:46:29 -0700 | [diff] [blame] | 719 | cmd+=( "${CHROOT_PASSTHRU[@]}" "$@" ) |
| 720 | exec chroot "${FLAGS_chroot}" "${cmd[@]}" |